Cisco Systems ASA 5580 Manual De Usuario

Descargar
Página de 712
 
23-6
Cisco ASA Series Firewall CLI Configuration Guide
 
Chapter 23      Configuring QoS
  Configuring QoS
(ASA 5512-X through ASA 5555-X) Priority queuing is not supported on the Management 0/0 
interface.
(ASASM) Only policing is supported.
Additional Guidelines and Limitations
QoS is applied unidirectionally; only traffic that enters (or exits, depending on the QoS feature) the 
interface to which you apply the policy map is affected. See the 
 for more information.
For traffic shaping, you can only use the class-default class map, which is automatically created by 
the ASA, and which matches all traffic.
For priority traffic, you cannot use the class-default class map.
For hierarchical priority queuing, for encrypted VPN traffic, you can only match traffic based on the 
DSCP or precedence setting; you cannot match a tunnel group.
For hierarchical priority queuing, IPsec-over-TCP traffic is not supported.
You cannot configure traffic shaping and standard priority queuing for the same interface; only 
hierarchical priority queuing is allowed.
For standard priority queuing, the queue must be configured for a physical interface or, for the ASA 
5505 or ASASM, a VLAN.
For policing, to-the-box traffic is not supported.
For policing, traffic to and from a VPN tunnel bypass interface is not supported.
For policing, when you match a tunnel group class map, only outbound policing is supported.
Configuring QoS
This section includes the following topics: